Published on:

March 2025

in:

Author/s:

 Rohit Kumar & Supriya Shekher Azad

AI Blindspots in India’s Privacy Law

Draft Rules under the Digital Personal Data Protection Act (DPDPA) – India’s maiden privacy law, were released for consultation last month. The Act, along with its Rules, seeks to regulate the use of personal data, and should ideally be technology-neutral. This means ensuring that it does not discriminate against certain technologies, and remains adaptable to regulate emerging ones.

Yet, the law reflects a weak understanding of the internet’s ongoing evolution – from decentralized websites to app-based systems, and now, AI-enabled experiences. For India to truly seize the AI opportunity, our laws must imbibe technology neutrality in letter and spirit, ensuring that they reasonably regulate not only existing technologies, but also emerging and future ones. Without this proactive foresight, the law risks over- or under-regulating technologies, straying from its intended purpose of responsibly guiding innovation.

Convoluted Public Data Exemption

Data is AI’s fuel. The more diverse the data, the better AI becomes — enhancing its understanding of language and varied contexts, as well as overall functionality. When utilized responsibly, personal data in training can help improve accuracy and service personalization. For instance, processing publicly-available information about public figures can help ensure greater accuracy when responding to questions about them.

An exemption has been carved out under the DPDPA for publicly available personal data, which may give the impression that AI models are free to train on such data. However, the exemption in its current shape is creating confusion for businesses, without effectively furthering user privacy. Here’s how – the exemption only applies to personal data caused to be made publicly available by the Data Principal or otherwise made public following a legal obligation. Such wording is needlessly convoluted – Singapore’s law, for instance, simply exempts data “that is publicly available”. Indian law, however, creates an arbitrary distinction based on who made the data public. 

Suppose your friend uploads a picture of you on their public blog without your consent. Since you didn’t cause it to be public, AI can’t use it for training. But if you uploaded the same picture, it can. This raises a fundamental question: Why should the determining factor be who made the data public, rather than sensitivity of data, risk of harm, or reasonable expectation of privacy?

A more effective approach would focus on the type of personal data involved, rather than its source of public availability, to avoid legal ambiguity. Taking guidance from thinking emerging in Australia and the EU, the law could introduce targeted requirements, such as defining clear collection criteria to limit training AI models to data reasonably expected to be public, prohibiting the use of sensitive categories like health records, and allowing entities to opt-out even if their data is publicly available.

The Case for Legitimate Interest

Another way to let AI responsibly train on personal data, without delving into the fact of its public availability, is to provide for a broader legitimate interest ground for processing. However, under the DPDPA, personal data may be processed only on two grounds — consent, and certain limited legitimate interests (national security, legal compliance, etc.). Notably, using personal data for AI training is not included as a permissible ground for such processing. Contrast this with the EU, known for its stringent data protection regime, which has a broader ‘legitimate interest’ ground. This means that if data is used for a justifiable purpose without causing harm to individuals, it can be processed without explicit consent. This makes sense when we consider the fallibility of the consent approach for large-scale AI training. Obtaining free, specific and informed consent from each individual who has rights in the data is practically unworkable. 

Let’s revisit our previous example; this time from a legitimate interest lens. If your personal data is publicly available without your consent, should AI be allowed to train on it under a legitimate interest framework? 

Ideally, the entity scraping the personal data should be made to answer three questions. One, does it have a valid interest behind scraping such data? For example, ingesting publicly available SOS posts for an AI model that identifies distress signals for disaster response. Second, is data scraping necessary for this purpose? Third, would the activity harm the rights of the individuals involved? This three-step test can help ensure responsible data collection and processing, and has been endorsed by data privacy regulators in the EU, as well as the UK. Such an approach to data processing can also help achieve the purpose of regulating personal data use for AI development, instead of relying on a complexly worded public data exemption.

In fact, instead of over-regulating use of input data, privacy laws could also be retargeted to place more robust guardrails at the output stage. It is here that heightened privacy risks such as responses inadvertently disclosing personal information arise.

Ambiguities around the research exemption 

Processing for research purposes is also exempted from the law’s ambit. A plain reading of the Act with the draft Rules would suggest that “research purposes” have no further qualifiers, and therefore commercial AI research is covered. However, the Explanatory Note released with the draft Rules muddies the waters, confining the exemption only to academic and policy research. It is therefore unclear if private firms building AI models can leverage the research exemption.

Outpaced by AI

DPDPA’s ambiguity and consent-centricity risk obsolescence amid AI’s rapid evolution. India needs a technology-neutral privacy law with clear, reasonable standards to regulate AI responsibly while not locking it in a rigid, outdated framework. Doing so requires a serious reconsideration of the DPDPA’s very philosophy and design. 

Rohit is the Founding Partner and Supriya was an Associate at The Quantum Hub (TQH) – a public policy firm

X (Twitter)
LinkedIn